Tag: Breach
-

The Vendor Incident Playbook
The vendor incident playbook has become the playbook the security team has been quietly trying to write, the playbook the breach response the vendor will produce has been quietly mocking, the playbook the next third party breach will demand.
-

Cloud Detection and Response: The Buyers Guide
The cloud detection and response buyers guide has become the guide the procurement team has been quietly trying to write, the guide the security team has been quietly trying to follow, the guide the vendor demo has been quietly trying to confuse.
-

A Field Guide to the Supply Chain Attack
The supply chain attack in 2026 sits as the dominant attack pattern in the typical enterprise breach, with the attacker compromising the vendor, the vendor distributing the malicious update, the enterprise installing the update, the enterprise getting breached. The SolarWinds, the 3CX, the xz utils near miss, the 2024 Snowflake credential theft, all the same…
-

The Data Your Browser Leaks Before You Click Anything
Before any JavaScript runs, before any consent banner, your browser is already giving the server enough information to identify you across visits. The cookie debate is over. The fingerprint debate is just starting.
-

Lateral Movement Without Exploits in 2026
Lateral movement without exploits in 2026 amounts to the dominant attack pattern in the typical enterprise breach. The attacker compromises one endpoint with a phishing email, the attacker uses the legitimate credentials the phishing email captured, the attacker moves to the next endpoint with the legitimate credentials, the attacker does not need a single exploit…
-

June 2026: The Month in Review
June 2026 in cybersecurity amounted to the month the breach fatigue caught up with the industry, with the major incidents slowing, with the regulatory actions intensifying, with the AI security maturing past the hype. The 2026 monthly review covers what happened, what mattered, and what the security leader should carry into Q3.
-

AI Models and Data Leakage in 2026
Every model that trains on your data remembers more of it than the provider’s privacy page suggests. The leakage problem is not the model’s fault. It sits in the prompts people send, the data they upload, the sessions they never close, the retention the vendor keeps for abuse monitoring.
-

Phishing Resistant MFA Deep Dive
Passwords died somewhere around 2022. The funeral for SMS codes happened in 2024. The survivors in 2026 sit at three: hardware keys, passkeys, certificate based auth. The choice between them runs as the choice the enterprise has been postponing for three years, and the postponement has cost enough breaches to retire the debate.
-

The State of Cryptography in Q2 2026
The cryptographic landscape in 2026 sits in a strange place. The algorithms everyone trusts are slowly becoming the algorithms nobody should trust, and the algorithms everyone should trust are still too new to deploy at scale. The migration has started, but the gap has not closed.
-

A Field Guide to the Incident Postmortem
The postmortem runs as the document nobody wants to write and everybody wants to read. Done well, it pays for itself the next time the same incident shows up in a different costume. Done badly, it sits in the compliance folder, the next incident hits the same gap, and the postmortem gets cited in the…